Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 17 Jun 2015 07:44:11 -0700
From: Tristan Cacqueray <>
Subject: [OSSA 2015-011.1] Cinder host file disclosure through qcow2 backing
 file (CVE-2015-1851) ERRATA 1

OSSA-2015-011.1: Cinder host file disclosure through qcow2 backing file

:Date: June 16, 2015
:CVE: CVE-2015-1851

- Cinder: versions through 2014.1.4,
          and 2014.2 versions through 2014.2.3,
          and version 2015.1.0

Bastian Blank from credativ reported a vulnerability in Cinder. By
overwriting an image with a malicious qcow2 header, an authenticated
user may mislead Cinder upload-to-image action, resulting in
disclosure of any file from the Cinder server. All Cinder setups are

CVE-2015-1850 has been assigned to a similar issue in Nova, the
correct CVE number for Cinder is CVE-2015-1851.

- (Icehouse)
- (Juno)
- (Kilo)
- (Liberty)

- Bastian Blank from Credativ (CVE-2015-1851)


- This fix will be included in future 2014.1.5 (icehouse), 2014.2.4
  (juno) and 2015.1.1 (kilo) releases.

OSSA History
- 2015-06-17 - Errata 1
- 2015-06-16 - Original Version

Tristan Cacqueray
OpenStack Vulnerability Management Team

Download attachment "signature.asc" of type "application/pgp-signature" (474 bytes)

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ